Listing Thumbnail

    Snyk Developer Security Platform (Deployed on AWS)

     Info
    Sold by: Snyk 
    Deployed on AWS
    AWS Free Tier
    Snyk is a developer security platform that finds and fixes vulnerabilities across code, open source, containers, and AI generated software from first line of code to production.
    4

    Overview

    Play video

    Software is being built faster than it can be secured, especially in the age of AI generated code and agentic development. Snyk gives developers and security teams a single platform to stay ahead of risk without slowing down delivery.

    Speed: Deploy in days. Get asset visibility and risk reduction fast. Scan in minutes with DeepCode AI. Auto PR checks and AI-powered AutoFix deliver verified fixes where developers work in the IDE, not a backlog.

    Coverage: One platform across your full attack surface. SAST, SCA, containers, IaC, secrets, DAST, and AI system security. Native integrations with GitHub, GitLab, Bitbucket, VS Code, AWS, and 20+ more tools your team already uses.

    AI Security: Snyk secures the systems that build your software, not just the code itself. Govern AI agent behavior, secure agentic development workflows, and maintain policy control as AI accelerates your software delivery.

    Highlights

    • Find and fix faster: Scan in minutes, not days. AI-powered AutoFix suggests verified fixes directly in your IDE and CI/CD pipeline.
    • Built for how you build today: Covers code (SAST), open source (SCA), containers, IaC, secrets, and AI generated code, with native integrations for GitHub, GitLab, VS Code, and AWS.
    • Proven at scale: 288% ROI, 75% faster remediation, 52% reduced breach risk across teams from startup to enterprise.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Snyk Developer Security Platform (Deployed on AWS)

     Info
    This product is available free of charge. Free subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    AI Insights

     Info

    Dimensions summary

    This listing has one option: Request Private Offer. You do not select a fixed plan or quantity here. Instead, you contact the vendor to arrange a custom quote through a private offer. The pricing scales to fit your needs, from individual plans up to Enterprise-level deployments. Because terms are negotiated directly, the specific price and developer count depend on the offer you receive. Snyk counts pricing per contributing developer, so your final cost reflects how many developers your organization needs to cover.

    Top-of-mind questions for buyers

    Snyk counts contributing developers, meaning anyone who commits to a private repository monitored by Snyk within the last 90 days. Contributions to public open source repositories do not count. Your developer total shapes the private offer you receive, since pricing is per contributing developer.
    A private offer can cover software composition analysis, static code analysis, infrastructure as code scanning, and container image scanning. Products can be purchased individually, but all products must fall within the same plan. Container scanning bundles with open source scanning. Your final scope depends on the negotiated offer.
    Snyk keeps separate test counts for each product and each plan. A test is a scan run against your code, dependencies, containers, or infrastructure files. Test limits vary by plan, so the scope negotiated in your private offer determines how many tests you can run.
    snyk.io
    Helpful?

    Vendor refund policy

    Fees are non-refundable and non-cancellable, except when required by law.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    As part of any Snyk plan, we offer live sessions, on-demand videos, downloadable content, hands-on practice and other self-serve resources designed to help you quickly and successfully derive value throughout your security journey with Snyk. Find all of this content in the Snyk User Hub. https://snyk.io/user-hub/  Submit a ticket:

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4
    20 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    20%
    75%
    5%
    0%
    0%
    4 AWS reviews
    |
    16 external reviews
    External reviews are from PeerSpot .
    Baljindra

    Early detection has reduced code vulnerabilities and protects production deployments

    Reviewed on Oct 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Snyk is to find vulnerabilities in the developed code, so once the developers develop the code and push to the repository, I need a tool that finds vulnerabilities before deploying to production.

    A specific example of how I used Snyk to find vulnerabilities before deployment is when developers are developing code and they directly push into production. Before implementing Snyk, we did not have any tool that finds a vulnerability before deployment. After deployment, CrowdStrike helps us to identify issues, but when developers are testing and writing code, I need a tool that finds vulnerabilities while it is being developed, so we should know if there are any vulnerabilities.

    Snyk helps me catch vulnerabilities earlier in the development process before anything goes to production because once the code is deployed to production, we do not want to disturb our production environment. I do not want to hamper our customers, so they have to wait on that, but I want to ensure that everything goes well before development.

    How has it helped my organization?

    Snyk has positively impacted my organization because before using it, we did not have any tool to identify vulnerabilities in the code before deployment. When I implemented Snyk in my environment, it helps to mitigate risks and also helps developers write perfect code without vulnerabilities. Therefore, it is a time-saving process, as we mitigate risks at the development stage rather than during deployment.

    Since using Snyk, it has reduced incidents significantly and also improves the code base. Earlier, we had multiple vulnerabilities, around 800 to 900 dependencies on the services we were using, but after implementing Snyk, it reduced those to 80 to 90 percent. The remaining issues are in the code base that is running on the old infrastructure, so we are transferring these with the help of Snyk. We follow its suggestions in the code base and after that we will take the necessary actions.

    What is most valuable?

    The best features that Snyk offers, which stand out the most to me, include Snyk CLI, integration with Jenkins, GitHub, Bitbucket, and integration with the Docker pods that we are running.

    The integrations with Jenkins, GitHub, Bitbucket, and Docker help my team day-to-day by being seamless and easy, allowing us to access my entire code base and scan for vulnerabilities or anything that goes wrong in the future. This also helps identify dependencies in my code base and mitigate how I should resolve those issues and vulnerabilities.

    Regarding the features, I find Snyk to be a simple tool that helps to mitigate risks and the dashboard is straightforward.

    Regarding Snyk's AI capabilities, I think its governance and security are reliable because Snyk uses GDPR to manage customer data and encryption techniques to secure the customer data code base without affecting anything, so it is a reliable service.

    In terms of Snyk's AI capabilities, I find that its accuracy and reliability of output are consistent. It is more reliable than what a human mind can do and AI provides a better way to handle tasks that developers are doing.

    What needs improvement?

    I think Snyk can be improved, but for a small organization that wants their tool free from vulnerabilities and dependencies with detection at the earliest stage, Snyk is the simplest and best way to do that.

    Regarding needed improvements, I have thoughts mostly on the pricing side, but the tool offers features that justify its cost.

    For how long have I used the solution?

    I have been using Snyk for around one year.

    What's my experience with pricing, setup cost, and licensing?

    I am using Snyk's licensing services with enterprise licensing, so I do not have to worry about how I am deploying that.

    I purchased Snyk through direct enterprise licensing from Snyk, not through AWS Marketplace or a different channel.

    What other advice do I have?

    The integration with the code base environment, local editors, Snyk CLI, and the ability to find Docker vulnerabilities through early detection and code base improvements with dependencies make it a perfect fit for my use case.

    Snyk is deployed in my organization.

    My advice for others looking into using Snyk is that small organizations wanting to improve their code base, increase efficiency, and remove dependencies can use Snyk CLI and Snyk vulnerabilities to find issues in their code and get reports and trends based on their developments.

    On a scale of one to ten, I rate Snyk a solid ten out of ten.

    Boya Uday Kumar

    Security upgrades have become faster and teams fix vulnerabilities earlier in development

    Reviewed on Aug 02, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Snyk involves finding and fixing security issues during application upgrades and migrations. In my work at ADP, I primarily use it to scan applications for vulnerabilities, identify risky dependencies, and help the team remediate issues before they become production problems. We had an initiative called Mythos where we had to upgrade the application and fix all security issues, and Snyk was very helpful during that time.

    In one of the Mythos upgrades, Snyk highlighted a dependency vulnerability that was buried in the package chain, which was not something we would have caught quickly by manual review. Because it surfaced early, we fixed it during the upgrade itself instead of dealing with it later, which immensely reduced the risk and kept the rollout on track. That was one of the incidents that I had with Snyk, and it was absolutely very helpful during this complete Mythos upgrade for all the team members.

    Another important part of how Snyk fits into my workflow is that it helps shift security left. Instead of waiting until the end of a project to discover vulnerabilities, we can catch them while we are still upgrading, migrating, or making any code changes. It also fits well into the developer workflow because it is just another plugin that we have in Visual Studio Code to be enabled to ensure all security issues are scanned and displayed visually. Once that is done, we can fix it in a matter of time, so having it as an extension in Visual Studio Code is one of the important things for developers because it becomes easily integrated into the workflow they are working with.

    What is most valuable?

    I find the most useful features of Snyk to be vulnerability scanning for code dependencies, containers, and infrastructure as code, with dependency intelligence that helps identify risky open-source packages and transitive issues. In major corporations like ADP, dependency intelligence is something that we actually care a lot about. I also like the fixed guidance feature, which includes upgrade suggestions and automated fixed pull requests. It has a developer-friendly workflow, so security issues show up where engineers already work, which is Visual Studio. We, as a team, appreciate two other important features: continuous monitoring, which helps us track risks even after the initial scan, and prioritization, allowing us to focus on the most important issues first.

    Dependency ingestion helps us see not just the direct package with the issue but also the transitive dependencies underneath it, which matters a lot because many security problems hide in nested libraries. Without that visibility, we might just miss the real root cause. It also helps the team judge whether a vulnerability is actually relevant to our application or just something we can safely deprioritize, saving us a lot of time during upgrades and migration work. Regarding fixed guidance, it is so valuable because it turns the scan result into an action. Instead of just telling us something is vulnerable, it often points us towards a safer version, an upgrade path, or a remediation option that we can apply quickly. That makes the team faster because developers do not have to investigate every issue from scratch, reducing back and forth between development and security review.

    Snyk had a very positive outcome on ADP and our workforce. The biggest positive outcome is less time spent on security remediation and fewer vulnerabilities carrying forward into later stages. Snyk's own metrics framework tracks open issues, new issues, resolved issues, PR checks, and time to fix, which maps well to the kind of benefits we saw in the Mythos initiative. The results included a 44% reduction in mean time to fix and a 62% reduction in critical vulnerabilities, along with an average of 2.2 development full-time employment worth of productivity gains. We saw a very positive impact mainly through time savings and earlier remediation as Snyk helped us catch vulnerabilities sooner during upgrades and migrations, reducing the effort for manual security issues. In practical terms, it improved a lot of developer productivity and helped the team fix security problems faster than ever with very little disruption.

    What needs improvement?

    Snyk could improve by reducing the alert noise because in large projects, security tools can surface a lot of findings. It helps when the platform is even better at highlighting what is truly urgent versus what can wait. Smarter prioritization would make it easier for developers to focus on the highest-risk issues first. Another area is workflow clarity during remediation. The fixed guidance is helpful, but it could be even better if the recommended path were more contextual, especially for complex dependency chains or upgrade conflicts. That would save a lot of time when teams are dealing with older applications and migration-heavy work.

    I would also like to mention reporting and governance visibility. More flexible dashboards, clearer trend views, or easier ways to track remediation progress across teams would help it be stronger for leadership and security reviews. That kind of visibility matters the most when we are trying to show improvement over time. These are the points I have in mind that could be improved by Snyk.

    For how long have I used the solution?

    I have been using Snyk for about eight months now, and it is absolutely valuable.

    What do I think about the stability of the solution?

    Snyk has been stable in our environment, and I have used it consistently during upgrades and security remediation work. It performs well without causing major disruption.

    What do I think about the scalability of the solution?

    Snyk scales well for our needs. As the number of applications and upgrades grows, it continues to fit into our workflow without adding much overhead, remaining useful for ongoing vulnerability detection and remediation across the team. We dealt with plenty of applications as a team, and Snyk grew with us. It was not a bottleneck, so I would say its scalability is top-notch.

    How are customer service and support?

    Customer support has been decent overall. When we needed help as a team, we approached them, and they are generally responsive and knowledgeable, though the experience can vary depending on the support level. The documentation is very strong, which reduces the need to go to support teams in most cases. I would rate the customer support as a 9 out of 10 because they are mostly knowledgeable, and Snyk definitely has very good documentation, leading to very little chance of needing to contact customer support.

    Which solution did I use previously and why did I switch?

    Before Snyk, we used a mix of manual dependency checks, local static scans, and an older open-source scanner as our primary tooling, but we switched to Snyk because it had the coverage and accuracy. Snyk's vulnerability database and dependency intelligence catch more transitive and emerging issues than the older scanner we used. It also integrates easily into the developer workflow because we have an extension in VS Code that we could leverage, and it offers automated fixed PRs along with clear upgrade guidance, dramatically reducing the time spent on researching remediation steps compared with our previous approach. The enterprise readiness, continuous monitoring, and analytics were other aspects that helped us choose Snyk over other older tools.

    What was our ROI?

    We definitely saw a measurable return on investment after adopting Snyk for the Mythos initiative, with the biggest wins being time savings and faster remediation. On average, we reduced the mean time to fix security issues by roughly 40 to 50% for the classes of vulnerabilities Snyk surfaced, which shortened our exposure window and reduced rework during upgrades. For ad hoc dependency issues and transitive vulnerability remediation, we estimate developer effort per vulnerability dropped from 8 to 16 hours down to about 2 to 4 hours, thanks to Snyk's dependency intelligence and automated fixed PRs. Across the initiative, that translated into thousands of developer hours saved and the equivalent of one to three full-time developers of effort reallocated to feature work instead of bug or patchwork.

    We also saw process benefits, with the number of critical, high-severity issues discovered late in testing or post-deployment dropping significantly. Roughly a 50 to 60% reduction for the targets we track, which reduced hotfix churn and decreased incident-related costs. Using Snyk in VS Code as an extension for CI pipelines meant many fixes were made pre-merge, and our PR blocking rate for high-risk vulnerabilities dropped, while the PR fix throughput increased. In terms of cost avoidance, faster fixes and fewer incidents reduced risk exposure and the potential remediation cost of production incidents. When combined with the time savings mentioned above, the team-level ROI is clear. The subscription cost is small compared to the developer hours recovered and reduced business risk during a major upgrade and migration program, so we saw a clear ROI, and it was very beneficial.

    What's my experience with pricing, setup cost, and licensing?

    Pricing and setup were fairly straightforward overall because Snyk has a free tier, with paid plans starting around $25 per contributing developer per month, and enterprise pricing is custom, so the cost relates to the team size and the level of features needed. Since we use Snyk as a VS Code extension, the onboarding effort is low, and the licensing model is easy to understand because it scales by contributing developer. Overall, it felt manageable for the team and made sense for the value it provided.

    Which other solutions did I evaluate?

    Before choosing Snyk, we looked at a few alternatives, such as SonarQube and GitHub Advanced Security, which we were actually using previously. We switched to Snyk because we thought it would be easily integrated into our developer workflow. Snyk has very useful features and was particularly beneficial during the Mythos upgrade, leading us to switch to Snyk across the teams.

    What other advice do I have?

    My advice would be straightforward: start with a clear use case and test Snyk in the workflow where your developers actually work. It is strongest when it is used early in the SDLC, especially for application upgrades, dependency checks, and fixing security issues before they reach production. I also suggest using it in a real project first, not just a demo, and paying attention to the dependency intelligence and fixed guidance because that is where it saves the most time. Evaluating Snyk on a real project and focusing on how well it fits into your daily development workflow is key. It is especially useful for catching vulnerabilities early, so the more closely you integrate it into your process, the more value you get. I would rate Snyk an 8 out of 10 overall.

    KannanPadmanabhan

    Automated security checks have blocked critical code issues and protect daily banking releases

    Reviewed on Feb 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are a customer of Snyk, which is a SaaS solution. We are one of the tenants using Snyk services but are not doing any enhancement development. We are purely a customer availing Snyk services.

    We are also using a separate DAST tool, though I am not aware of the tool name as it is managed by a different team.

    We utilize two main capabilities: application vulnerability detection and SCA capabilities. The primary reason we use Snyk is for SAST, as we want to scan our applications for any security vulnerabilities and address them.

    What is most valuable?

    Snyk is finding all the issues we have. It suggests solutions for every vulnerability, and we are getting patches frequently. As someone from an enterprise, I want to share feedback that might help others. There are multiple teams involved in our organization. We have a separate cyber team that works with Snyk and keeps on updating, though I am not fully aware of all the details in that area.

    What needs improvement?

    I have not explored from that perspective. Being from an application perspective, I cannot say anything that needs real improvement. I have not explored from that angle. Till now, we did not face any scaling issues and I did not hear of any. I would rate this at 9 because I always keep one number in reserve, as there is always scope for improvement for any tool.

    For how long have I used the solution?

    We have been using Snyk for more than a year.

    What do I think about the scalability of the solution?

    Till now, we did not face any scaling issues and I did not hear of any. I would rate this at 9 because I always keep one number in reserve, as there is always scope for improvement for any tool.

    How are customer service and support?

    We do not raise issues directly with Snyk. We have a common team that liaises with Snyk. Whenever we have issues, we raise them with the cybersecurity team within our company who supports Snyk, and they in turn interact with Snyk.

    Which solution did I use previously and why did I switch?

    Earlier, I used Checkmarx, which is another SAST tool. By default, any company and any SAST tool like Checkmarx or Snyk provides a plugin.

    What about the implementation team?

    Snyk is integrated. I have not used it directly, though I may have used it indirectly.

    What other advice do I have?

    I am from an enterprise and want to share feedback that might help others. There are multiple teams involved in our organization. I am from the application team, so I know the vulnerabilities and how to fix them. However, there is a platform team that takes care of giving permission for Snyk and access levels, which I am not fully aware of. At a high level, we have a Snyk admin team in our company that gives permissions, though I do not know all the details of what they do. I cannot share feedback on the admin area, but I can share that vulnerability-wise, I am happy with what Snyk provides and the solutions it gives.

    When Snyk identifies issues, our pull request process will not allow us to merge them in the first place. Snyk helps us by blocking critical issues and vulnerabilities. If someone bypassed the pull request check, we have another check in place before production release where we validate everything and block the code if it violates our standards. Based on Snyk categorization, we block issues from our end while raising a pull request and also before releasing to production.

    We need Snyk because we are in the banking industry with thousands of applications. Every day, we deploy code to production, releasing almost every day except weekends, though we sometimes release on weekends for very large deployments. Anything that goes to production should not have any security vulnerabilities. Being in the banking industry and having applications used by end customers, we are dealing with end customer data. No one should steal data in any format, and with authentication, one user cannot see another user's data. Snyk is paramount and extremely important for us. Every application that goes into production must pass Snyk vulnerability scanning before it can be deployed. If you ask whether it is important, it is absolutely critical. I would rate it 10 out of 10.

    Internally, whenever a Snyk scan runs, we have created GitHub Actions. Our target state is GitHub Actions everywhere. When we run the GitHub Actions, it will connect to the latest Snyk scanning through API and automatically gets all open issues, then creates a GitHub issue. First, our internal tool pulls out all Snyk security issues through the API and creates GitHub issues. We manually open a GitHub issue and give a command prompt to our AI agent. That prompt internally might work with Snyk autofix capability and gets the fixes correctly and creates a pull request. We review and check in the pull request, which is reviewed by experienced team members. This is the process we follow: create an issue based on a Snyk scan and for every issue, run a prompt so that it creates a pull request automatically with the fixes.

    We do use Snyk documentation. We internally do not have many resources because we do not want to duplicate. Snyk guide is purely open and not logged in, so we use it.

    Snyk documentation is extremely useful. Vulnerability-wise, I do not go to Snyk documentation frequently because in the current world, with my 25 plus years of experience, I used to fix many things manually before these tools existed. I need to know the intricacies of how to fix code. If you take 10 years back, there were tools and libraries which you could integrate with one or two lines, which solved the problem. With the current AI world, I do not even need that. If I get some issues, I do not even need to go to the Snyk website and read how to fix. I have an AI tool that can fix it if I ask it to. From an engineer's perspective, I still read the documentation. As a person who came from the manual world 25 years back, I still read the fix documentation. The documentation is very good, and being a general one, I understand the SAST world, so I did not find much problem with the documentation.

    We are using Snyk, which is a SAST tool. There is a team in our organization who developed some AI agent on top of Snyk capabilities. I do not know exactly how they integrated Snyk, but our organization provides an AI agent which, if we run, automatically fixes issues and raises a pull request. In that case, we are indirectly using Snyk.

    My overall rating for Snyk is 10 out of 10.

    Abhishek-Goyal

    Improves security posture by actively reducing critical vulnerabilities and guiding remediation

    Reviewed on Nov 15, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I typically use Snyk for checking the security and vulnerabilities in my repositories.

    Recently, I have used Snyk in one of my repositories for security and vulnerability checks, providing comprehensive knowledge about the repository, including what it does and where the security vulnerabilities are located.

    I am using Snyk for the first time and did not use any vulnerability scanning solution before this. I was previously doing Red Hat vulnerability scanning locally for dependency checks, which was not what I wanted.

    What is most valuable?

    Snyk's main features include open-source vulnerability scanning, code security, container security, infrastructure as code security, risk-based prioritization, development-first integration, continuous monitoring and alerting, automation, and remediation. The best features I appreciate are the vulnerability checking, vulnerability scanning, and code security capabilities, as Snyk scans all open-source dependencies for known vulnerabilities and helps with license compliance for open-source components.

    Snyk integrates into IDEs, allowing issues to be caught as they appear in the code dynamically and prioritizes risk while providing remediation advice.

    Snyk provides actionable remediation advice on where vulnerabilities can exist and where code security is compromised, automatically scanning everything and providing timely alerts.

    Snyk has positively impacted my organization by improving the security posture across all software repositories, resulting in fewer critical vulnerabilities, more confidence in overall product security, and faster security compliance for project clients.

    Snyk has helped reduce vulnerabilities significantly. Initially, the repository had 17 to 31 critical and high vulnerabilities, but Snyk has helped manage them down to just five vulnerabilities, which are now lower and not high or critical.

    What needs improvement?

    Although Snyk is strong, sometimes it flags vulnerabilities that are not reachable, not exploitable, and not relevant to a project. Better reachability analysis and context-aware scanning could improve this.

    Snyk could benefit from a more optimized scanning engine and incremental scan caching.

    For how long have I used the solution?

    I have been using Snyk for the previous one year.

    What do I think about the stability of the solution?

    I have no issues with Snyk's reliability; it is stable.

    What do I think about the scalability of the solution?

    Snyk is very scalable and can handle my organization's growth and changing needs, allowing us to scale up to many stages and reduce developer costs, especially when we have fewer developers.

    How are customer service and support?

    I never reached out to customer support because I never encountered any issues.

    Which solution did I use previously and why did I switch?

    I considered SonarQube in detail before choosing Snyk.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is good, as the overall setup experience is smooth with easy onboarding for connection with GitHub and GitLab. I primarily use it with GitHub, requiring just a few clicks to set up Snyk.

    What was our ROI?

    I can see that Snyk saves the costs of hiring security developers for vulnerability scanning and security checks, as that responsibility is now managed by Snyk.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is good for small teams, with a free tier or low-usage pricing available, and the licensing experience is straightforward but not very flexible.

    What other advice do I have?

    My advice for others looking into using Snyk is that if you are starting a repository that is free from vulnerabilities and security checks, Snyk is a good option. It automatically provides advice on how to improve for reducing vulnerabilities and security issues, allowing for easy removal of vulnerabilities. You can use it for a free trial, and if it impacts your organization positively, you can consider further usage.

    Snyk is a very good product for vulnerability code scanning and can be used effectively. I would rate this product a nine point five out of ten.

    ANDRESANTOS

    Has improved development workflows through early vulnerability detection and accurate insights

    Reviewed on Sep 23, 2025
    Review from a verified AWS customer

    What is our primary use case?

    The most recent client had experience with other products that did not have some features Snyk provides, such as Fortify in the old version before OpenText acquisition. They gave feedback about the precision in discovering vulnerabilities. They found that Snyk can provide more insights about vulnerabilities than older applications in SAST and SCA.

    We have integration with GitHub Actions to analyze the code and we use a double check in the pipeline. Our strategy is about shift left. The developers connect with Snyk, Git, and use this with the pipeline.

    How has it helped my organization?

    They evolved their maturity because they could find the vulnerabilities before the pipeline runs. They can find and correct these vulnerabilities in a step before the pushes and PRs to GitHub. They think it is a very positive feature.

    What is most valuable?

    I appreciate the UI. It is simple, fast, and I value the precision in the tests. The responses are positive.

    Regarding the vulnerability database and AI, we have good experience with that. I cannot compare with other providers or vendors such as Veracode, Checkmarx, and others. All the tests are positive in my analysis.

    What needs improvement?

    Technically, we have better vulnerabilities detection in Checkmarx and Veracode. Both of them are more precise about vulnerabilities detection. Snyk is slightly less effective, but this is something they can improve on in the future.

    For how long have I used the solution?

    We have been using the solution for one and a half years. Not much time.

    What do I think about the stability of the solution?

    We did not need support during the proof of concept.

    How are customer service and support?

    The documentation is good. It is one of the reasons we did not need support. We could understand the implementation of the product and other features without the need for human interaction.

    Which solution did I use previously and why did I switch?

    I made a proof of concept for a client with Checkmarx for about one month. I provided them a review about my experience. Now they are analyzing my results and considerations about other products too. I do not know if they already have a response about which product they will buy.

    What's my experience with pricing, setup cost, and licensing?

    Snyk is less expensive.

    Which other solutions did I evaluate?

    It is simpler than other vendors. We have some difficulties with other license models. They are more complex and involve an acquisition of more products such as Synopsys and Checkmarx used a complex license model. Snyk has a license model simpler than most of the other vendors.

    What other advice do I have?

    It was one of my three recommendations for my client. I am satisfied with the product. I rate Snyk 8.5 out of 10.

    View all reviews